| ID: | 16981 |
|---|---|
| 标题: | CVE-2018-16509 |
| 描述: | 在文件上传过程中,有可能会用GhostScript来处理图片。所以在上传图片点可以试一下它是否存在这个漏洞。在处理/invalidaccess异常时,程序没有正确的检测restoration of privilege(权限恢复)。攻击者可通过提交特制的PostScript利用该漏洞执行代码。 |
| 类型: | RCE漏洞 |
| 网站: | cyberstrikelab |
| 题目链接: | https://www.cyberstrikelab.com/ |
| 赛事: | cyberstrikelab |
| 年度: | 2018 |
| Flag值: | 无 |
| writeup: |
https://blog.csdn.net/niubi707/article/details/128147965 无 https://www.secnn.com/POC-EXP/site/Web%E5%BA%94%E7%94%A8%E6%BC%8F%E6%B4%9E/Python/PIL-CVE-2018-16509/README.zh-cn/ |